IBM QRadar Suite Stores Sensitive Information in Log Files
CVE-2024-22337
5.5MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 17 February 2024
Summary
IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279977.
Affected Version(s)
Cloud Pak for Security 1.10.0.0 <= 1.10.11.0
QRadar Suite Software 1.10.12.0 <= 1.10.17.0
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved